CVE-2025-66020

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-66020
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66020.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66020
Aliases
Published
2025-11-26T01:49:38.276Z
Modified
2025-12-05T10:21:54.127378Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Valibot has a ReDoS vulnerability in `EMOJI_REGEX`
Details

Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. A short, maliciously crafted string (e.g., <100 characters) can cause the regex engine to consume excessive CPU time (minutes), leading to a Denial of Service (DoS) for the application. This issue has been patched in version 1.2.0.

Database specific
{
    "cwe_ids": [
        "CWE-1333"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66020.json"
}
References

Affected packages

Git / github.com/open-circle/valibot

Affected ranges

Type
GIT
Repo
https://github.com/open-circle/valibot
Events

Affected versions

1.*

1.0.0-beta.0-to-json-schema

v0.*

v0.1.0-to-json-schema
v0.1.1-to-json-schema
v0.2.0-to-json-schema
v0.2.1-to-json-schema
v0.31.0
v0.31.1
v0.32.0
v0.33.0
v0.33.1
v0.33.2
v0.33.3
v0.34.0
v0.35.0
v0.36.0
v0.37.0
v0.38.0
v0.39.0
v0.40.0
v0.41.0
v0.42.0
v0.42.1

v1.*

v1.0.0
v1.0.0-beta.0
v1.0.0-beta.0-i18n
v1.0.0-beta.1
v1.0.0-beta.1-i18n
v1.0.0-beta.1-to-json-schema
v1.0.0-beta.10
v1.0.0-beta.11
v1.0.0-beta.12
v1.0.0-beta.13
v1.0.0-beta.14
v1.0.0-beta.15
v1.0.0-beta.2
v1.0.0-beta.2-i18n
v1.0.0-beta.2-to-json-schema
v1.0.0-beta.3
v1.0.0-beta.3-to-json-schema
v1.0.0-beta.4
v1.0.0-beta.4-to-json-schema
v1.0.0-beta.5
v1.0.0-beta.5-to-json-schema
v1.0.0-beta.6
v1.0.0-beta.7
v1.0.0-beta.8
v1.0.0-beta.9
v1.0.0-i18n
v1.0.0-rc.0
v1.0.0-rc.0-i18n
v1.0.0-rc.0-to-json-schema
v1.0.0-rc.1
v1.0.0-rc.2
v1.0.0-rc.3
v1.0.0-rc.4
v1.0.0-to-json-schema
v1.1.0
v1.1.0-to-json-schema

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66020.json"